AIMedium

Anthropic opens three-tier cyber access program as Glasswing tallies 129,000 flaws

Anthropic merged its Cyber Verification Program and Project Glasswing into a three-tier scheme giving vetted defenders and red teams access to models with fewer cyber safeguards.

Anthropic opens three-tier cyber access program as Glasswing tallies 129,000 flaws

At a glance

  • The revamped Cyber Verification Program offers Defense, Red Team and Specialized Access tiers.
  • Red Team Access is limited to organizations; actions such as deploying ransomware remain blocked.
  • Glasswing partners found at least 129,000 verified vulnerabilities between April and July, the company said.
  • More than 33,000 of the reported flaws are rated critical or high severity.

Anthropic has revamped its Cyber Verification Program (CVP), merging it with Project Glasswing into a single three-tier scheme that gives vetted security teams access to its most capable models with fewer cyber-related safeguards, SecurityWeek and The Hacker News reported on October 7. The company also disclosed that Glasswing partners found at least 129,000 verified software vulnerabilities between April and July, a figure it says is likely an undercount.

What happened

According to SecurityWeek, Glasswing previously gave organizations securing critical software access to the Mythos model, while the original CVP relaxed safeguards on Opus and Sonnet models for approved teams. All three new tiers include Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models, each with its own verification requirements and controls. Anthropic said it offers these capabilities to defenders because they are dual-use and could be weaponized by attackers, The Hacker News reported.

How the tiers work

Defense Access covers SOC and incident response, malware reverse engineering and vulnerability analysis. Security teams, critical infrastructure operators, small security firms, open source maintainers and individual researchers with a disclosure history can apply, and Anthropic aims to respond within days, SecurityWeek said.

Red Team Access adds authorized penetration testing and red teaming on systems the organization is permitted to test. Actions that could cause physical harm or mass disruption, such as deploying ransomware, remain blocked in real time. "Currently, this tier is for organizations only; individual researchers are not eligible," the company said.

Specialized Access has the fewest cyber blocks and is reserved for a small number of organizations authorized to test safety-critical systems such as power grids, flight systems, telecom networks and interbank transfer infrastructure. SecurityWeek reported that Anthropic is vetting these applicants with the US government and that existing Glasswing members are moving into this tier.

Participants must accept data retention so the company can monitor for misuse, with limited zero-data-retention options. The Hacker News cited internal tests on 50 tasks in which Defense Access safeguards blocked 46, while Red Team Access blocked none.

Vulnerability figures

Anthropic said its own open source scanning found another 5,500 verified flaws between April and October, and that more than 33,000 of all reported vulnerabilities are rated critical or high. "This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners," the company said, estimating the real impact at least five times higher. The figures have not been independently verified, and neither report says how many flaws have been patched.

For context, The Hacker News cited VulnCheck research finding that 2 of 300 vulnerabilities credited to Anthropic or Glasswing had been exploited in the wild, including CVE-2026-61500 in Rejetto HTTP File Server.

Why it matters

The program formalizes how security teams can use frontier models for offensive testing, a capability vendors have so far restricted. Organizations interested in access should review the tier requirements, data retention terms and the scope of systems they are authorized to test before applying.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.